Question

In: Computer Science

Case-IT Auditing ABC has a sound change management process/policy for program code changes that includes the...

Case-IT Auditing

ABC has a sound change management process/policy for program code changes that includes the ability for users to request changes which are entered by users through a web based internally managed portal (CMP)ICS). User requests are then electronically routed to the appropriate IT and business personnel for review and approval to proceed to work the request. Once IT completes the coding revisions and performs unit and system testing, then users will test the system changes. Upon satisfactory testing the users will formally approve the movement of code to production using the web-based change portal. IT will then work with the business areas to move the code from the test environment to production at the agreed to time. All testing support is retained. ABC IT department maintains a downtime window on Sundays that allow time for code migrations. Additionally, this same downtime window allows for appropriate full backups to occur for all systems. During the week incremental backups occurs.

Question: What are the Controls and what are the GAPS

Solutions

Expert Solution

Controls:

IT general controls (ITGC) are the basic controls that can be applied to IT systems such as applications, operating systems, databases, and supporting IT infrastructure.

The objectives of ITGCs are to ensure the integrity of the data and processes that the systems support. The most common ITGCs are as follow:

  • Logical access controls over applications, data and supporting infrastructure
  • Program change management controls
  • Backup and recovery controls
  • Computer operation controls
  • Data center physical security controls
  • System development life cycle controls

GAPS:

The Assessor will:

• Review the compliance of your management system to the requirements of the appropriate
standard
• Document where your system complies / does not comply with the certification requirements
• Discuss what needs to be considered in the project plan and agree any corrective actions

A report will be raised:

• Confirming the areas of the standard that your organization is currently conforming
• Identifying any areas that are not conforming
• Provide the foundation for a project plan

This report will enable your business or organization to implement a plan to remedy these gaps in readiness for the mandatory initial audits for certification.

Hope this helps. :-)


Related Solutions

Case Management Process and implementing change (motivational interviewing, change process with precontemplation to maintenance).
Case Management Process and implementing change (motivational interviewing, change process with precontemplation to maintenance).
Auditing the revenue process and Auditing the inventory management process. What is the importance?
Auditing the revenue process and Auditing the inventory management process. What is the importance?
Auditing Audit planning is the first step in the audit process. It includes understanding the client’s...
Auditing Audit planning is the first step in the audit process. It includes understanding the client’s business and industry and performing preliminary analytical procedures to assess client business risk and other kinds of risks that could affect the audit process.  Describe the importance of audit planning and how it affects the remaining of the audit process. ( In a paragraph form if possible ,would be great to answer it ).
Grow Management Consultants has recently implemented a work-life balance policy. The policy includes a new initiative...
Grow Management Consultants has recently implemented a work-life balance policy. The policy includes a new initiative to hold a quarterly social event for all staff. As the Operations Manager (you) for Grow Management Consultants, you have decided to have an informal meeting with your staff to seek their ideas on social activities and to discuss timing (e.g. which days of the week work best, what time). Note that the policy states that a maximum budget of $500 per activity may...
tcja change the depreciation rules for new Farm machinery and equipment the changes includes
tcja change the depreciation rules for new Farm machinery and equipment the changes includes
Nestlé has found changes in China a challenge to deal with. Explain why change management is...
Nestlé has found changes in China a challenge to deal with. Explain why change management is important for international business, and what changes in the host country’s environment can affect the company’s overseas operations.
For each of the following policy changes, explaim why the change is or is not likely...
For each of the following policy changes, explaim why the change is or is not likely to be a Pareto improvement. a) Building a park, financed by an increase in the local property tax rate b) Building a park, financed by the donatiom of a rich philanthropist c)Increasing medical facilities for lung cancer, financed out of a general revenues d)Increasing medical rate facilities for lung cancer, finances out of an increase in the cigarette tax
Which of the following policy changes would be considered a conventional monetary policy change? -Announcing a...
Which of the following policy changes would be considered a conventional monetary policy change? -Announcing a firm policy to conduct large scale open market purchases in the future. -An open market sale of securities to increase the fed funds rate. -Federal Reserve lending through the Term Auction Facility -Purchases of long-term securities to lower long-term interest rates. Which of the following policy changes would be considered an unconventional monetary policy change? -An open market purchase of securities to decrease the...
Define monetary policy. Describe the mechanism that leads from a change in monetary policy to changes...
Define monetary policy. Describe the mechanism that leads from a change in monetary policy to changes in interest rates, exchange rates, and the current account balance.
Program in Java code Write a program with total change amount in pennies as an integer...
Program in Java code Write a program with total change amount in pennies as an integer input, and output the change using the fewest coins, one coin type per line. The coin types are Dollars, Quarters, Dimes, Nickels, and Pennies. Use singular and plural coin names as appropriate, like 1 Penny vs. 2 Pennies. .Ex1: If the input is: 0 the output is:    No change            Ex2: If the input is:    45   the output is:   1 Quarter 2 Dimes
ADVERTISEMENT
ADVERTISEMENT
ADVERTISEMENT